发明名称 Assigning user requests of different types or protocols to a user by trust association interceptors
摘要 A Universal TAI handles multiple identifications by means of an internal lookup table. When authenticating and authorizing requests, from a pre-registered customer, that are serviced by an application server, a reverse proxy security server receives requests of different protocols and associates user identification information of a single user with different formats based on the types and protocols of the requests. The Universal TAI determines a fundamental identification of the user from a lookup table, substitutes the fundamental identification into the requests of different protocols for the same user principal, and passes the request with the fundamental identification to the application server.
申请公布号 US9590990(B2) 申请公布日期 2017.03.07
申请号 US200912463583 申请日期 2009.05.11
申请人 International Business Machines Corporation 发明人 King Jennifer E.;Smith Timothy J.;Wrobel, Jr. Anthony W.
分类号 G06F7/04;H04J3/16;H04B1/40;H04L29/06;G06F9/445 主分类号 G06F7/04
代理机构 CRGO LAW 代理人 Greenberg, Esq. Steven M.;CRGO LAW
主权项 1. A computer-implemented method for authenticating and authorizing requests from a user that are serviced by an application server, comprising: receiving at different times in a reverse proxy security server a first request in accordance with a first communications protocol and a second request in accordance with a second communications protocol that is different than the first communications protocol, both protocols being received in association with a same end user; creating, by the reverse proxy security server in response to receiving the first request, a modified form of the first request by retrieving user identification information for the end user, modifying the first request to include the user identification information formatted in accordance with the first communications protocol, and dispatching the modified form of the first request to an application server in which a universal trust association interceptor executes; creating, by the reverse proxy security server in response to receiving the second request, a modified form of the second request by retrieving the user identification information for the end user, modifying the second request to include the user identification information formatted in accordance with the second communications protocol, and dispatching the modified second request to the application server; and, responding a receipt of the first request in the universal trust association interceptor, by looking up in a lookup table a fundamental identification corresponding both to the user identification information in the first communications protocol, and also the first communications protocol, substituting in the first request the fundamental user identification for the user identification information to create a first fundamental identification request, and passing the first fundamental identification request to the application server, but responding to a receipt of the second request in the universal trust association interceptor, by looking up in the lookup table the fundamental identification corresponding both to the user identification information in the second communications protocol and also the second protocol, substituting in the second request the fundamental user identification for the user identification information to create a second fundamental identification request, and passing the second fundamental identification request to the application server.
地址 Armonk NY US